Connect with us

E-Business

Africa’s Data Security Readiness at Low Levels – Report

Published

on

Kindly share this post

Despite a high level of IT security awareness and robust corporate IT governance policies in Africa, the level of data security preparedness is still very low.

This is according to the 2019 “State of Information Security Preparedness in Africa: Data Protection Survey”, compiled by information risk solutions provider, Arcon Techsolutions.

More than 100 industry IT professionals, CIOs and CISOs from Kenya, Nigeria, SA and Ghana were surveyed to establish the state of Africa’s IT and data security preparedness.

The survey highlights that African organisations remain increasingly vulnerable to data breaches. As a result, organisations will have to reinforce their privileged access to secure confidential and sensitive corporate data.

Root cause

Advertisement

The majority of the survey participants believe the root cause for the steep rise in data breaches on the continent is mainly due to a compromised user or privileged account, with 79% of the survey participants agreeing to that fact.

Unfortunately, the awareness alone is not enough to build up a secure IT environment, notes the survey.

“Implementing best privileged account management practices like access based on only need-to-know and principle-of-least-privilege, along with frequent randomisation of privileged credentials, can make the IT security posture more robust.”

According to the survey, 74% of the participants accepted that privileged access management (PAM) is a major area of concern for information security.

Paresh Makwana, cyber security expert and business development consultant at Arcon Techsolutions, says organisations’ IT attack surface expands when adequate attention is not given to secure the access control mechanism.

Advertisement

“Typically, administrative accounts are targeted by malicious insiders or compromised third-party users and sometimes organised cyber criminals. They are always on the lookout to steal or misuse information by making an unauthorised access to target systems.

“Privileged access management practice helps an organisation to establish a rule- and role-based centralised access control policy over users. Therefore, any malicious attempt to breach sensitive information is prevented and the IT administrator receives alert messages about the suspicious activities.”

The survey adds: “To overcome these enormous IT pain-points and secure enterprise databases and critical business applications from malicious activities, enterprises need to adopt best privilege account management practices.

“Privileged access management offers the security team with a foundation to build a robust mechanism to manage, monitor and control privileged identities as every access to target systems is authorised, authenticated and documented.”

Governing policies

Advertisement

Responding to the question whether their companies follow digital or cyber governance policies, most of the participants (88.3%) acknowledged they have information security and governance policies within their organisations.

However, according to the survey, hardly any of those policies emphasise the security of privileged accounts that are the gateways to crucial and confidential data. “Most of the organisations confessed they have not invested in privileged access management solutions to date, which is a matter of genuine concern.”

Three percent of the respondents revealed they don’t know whether their companies follow information security and governance policies, while 7.8% indicated they are unaware.

Under discussion

In regards to the issue of data theft as a key topic within boardroom discussions, 50.6% of the survey respondents indicated ‘no’ to that question, with 44.2% saying ‘yes’. The remainder (5.3%) were ‘not sure’.

Advertisement

The survey states: “In spite of rampant data breach incidents hurting organisations, surprisingly, around 50.6% of respondents believe data theft is not a recurrent subject of boardroom discussions.

“IT security personnel should make this matter more pronounced to the management and board so that everyone is on the same page regarding steps taken to mitigate data security threats.”

Fear factor

Answering the question to what they fear the most, 33.7% highlighted phishing or malware remains the top of the list of their security threats.

The survey also observes that three-quarters of security professionals surveyed fear third-party IT users, insiders and targeted attacks.

Advertisement

“It is important to note the IT attack surface widens due to unmonitored privileged accounts. Malicious third-party IT users, disgruntled corporate insiders and organised cyber criminals snoop privileged credentials to target confidential information.”

Money matters

The survey participants (48%) felt the IT risk and security management team would like to invest in PAM, followed by database activity monitoring (41.55%) and identity access management (36.36%).

In addition, 33.76% voiced their opinion for security compliance management and mobile device management, according to the survey.

“Governance, risk and compliance is also seen as a matter of concern because almost 25.97% respondents held that opinion; and finally, 11.68% respondents felt both identity access management and PAM technologies will be critical IT security investment areas.”

Advertisement

Kindly share this post

Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

Continue Reading
Advertisement
Comments

E-Business

82% of Organizations Concerned about AI Risks Even as Adoption Accelerates – Survey Reveals

Published

on

Kindly share this post

At its recent Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region Kaspersky shared the results of a global study conducted by its internal research center which surveyed 1,800 IT and cybersecurity decision-makers and specialists from organisations across 18 countries and multiple industries.

The report shows that the pace of AI integration across organisations is rapid, despite associated risks. The company’s experts stressed that while AI adoption delivers clear efficiency gains, it must be accompanied by robust cybersecurity solutions, well-defined internal procedures, and comprehensive employee education programmes.

The report highlights a clear organisational preference for AI-enhanced technology: 68% of respondents said they would recommend a solution with AI features built in, while a mere 5% indicated they would prefer to avoid AI-enabled tools. This overwhelming endorsement underscores how deeply AI has embedded itself as a value driver across the modern enterprise.

AI has become a mainstream productivity tool spanning many business functions. The global survey findings confirm that employees across departments are already relying on AI tools for a wide range of everyday tasks, including: data analysis & visualisation (54%), project management (49%), search for information (47%), department-specific tasks (46%), text generation and editing (41%).

While organisations recognise the tangible benefits AI tools bring – including improved process efficiency and enhanced quality of deliverables – they also see the associated dangers. 82% of respondents voiced concerns about the risks AI poses to their organisation. These concerns are grounded in real-world experience.

Advertisement

Among the 87% of organisations worldwide that faced a cyber incident in the past year, 13% reported that they had experienced threats stemming specifically from AI-related vulnerabilities.

Notably, 74% of respondents believe that these risks can be effectively mitigated through employees’ responsible behaviour — pointing to the critical importance of security awareness and training in the AI era.

“The speed at which organisations are embracing AI is remarkable, but it must be matched with an equally strong commitment to security. We are already seeing a growing range of threats directly tied to AI adoption – whether it’s malware camouflaged as popular AI tools, vulnerabilities introduced through unsecure vibecoding, or leaked access credentials to corporate AI platforms and malicious skills by AI agents.

Managing these risks requires a holistic approach: the right technology, well-defined procedures, and a security-aware workforce,” comments Brandon Muller, senior security consultant for the META region at Kaspersky.

Advertisement

Kindly share this post
Continue Reading

E-Business

How Temu Helped a Madagascan Vanilla Family Business Sell Direct to Consumers Across Europe

Published

on

Kindly share this post

Malagasy Vanilla has transformed its decades-old wholesale business by embracing direct-to-consumer sales through Temu, enabling the family-run company to reach customers in 14 European markets while significantly reducing logistics costs.

How Temu Helped a Madagascan Vanilla Family Business Sell Direct to Consumers Across Europe

For years, premium Madagascan vanilla supplier Malagasy Vanilla sold exclusively to restaurants, bakeries and wholesalers because the cost of shipping a single pack to individual customers often equalled the value of the product itself. That changed after the company joined Temu’s Local Seller Program in November 2025.

The Belgian-based business, which sources high-quality vanilla from Madagascar, has leveraged Temu’s logistics network to cut domestic shipping costs by nearly half through a partnership with Belgian postal operator Bnode. The move has enabled the company to enter the retail market for the first time and quadruple its sales within four months.

According to Belinda Rabenandrasana, co-Chief Executive Officer of Malagasy Vanilla, Temu has opened up an entirely new customer segment for the company.

“Temu opened a new avenue for us,” she said. “We were finally able to explore selling to individuals.”

Advertisement

The platform now contributes between five and 10 per cent of the company’s overall revenue.

Expansion into 14 European Markets

Malagasy Vanilla is among businesses participating in Temu’s Local Seller Program, launched in Europe in 2024 to help local merchants expand beyond their domestic markets.

Through partnerships with more than 150 logistics providers across Europe—including Bnode in Belgium, La Poste in France and DHL Group in Germany—Temu offers sellers access to affordable shipping and delivery infrastructure without requiring major investment in logistics.

After successfully establishing direct-to-consumer sales in Belgium, Malagasy Vanilla expanded into 14 European countries, including Germany, France, Spain and Poland.

Rabenandrasana said the logistics support, competitive shipping rates and seller assistance provided by Temu made the expansion possible.

Advertisement

“Without Temu and its partnership with Bnode, it would have been very difficult for a small business like ours to start selling directly to consumers,” she said.

She added that Temu also assists sellers in managing regulatory requirements such as the European Union’s Extended Producer Responsibility (EPR) compliance, making cross-border operations easier for small businesses.

Three Generations of Vanilla Expertise

Malagasy Vanilla traces its roots to three generations of the Rabenandrasana family in Madagascar’s vanilla industry.

Belinda’s grandfather began trading vanilla locally, while her father expanded operations across Madagascar. She launched the company’s international business in 2017, supplying premium Madagascan vanilla to European restaurants, pastry shops and food wholesalers before establishing operations in Belgium in 2023.

The company partners with growers and producer associations in Madagascar, where between 20 and 40 workers oversee the six- to 10-month curing process that transforms green vanilla pods into premium black vanilla.

Advertisement

Operations in Belgium focus on packaging, quality assurance and distribution.

Customer Reviews Drive Growth

Under its Lavani brand, Malagasy Vanilla sells gourmet-grade whole vanilla pods targeted at both professional chefs and home baking enthusiasts.

Rather than relying heavily on paid advertising, the company has benefited from Temu’s product discovery tools and customer reviews, helping the niche brand gain visibility organically.

According to Rabenandrasana, strong customer feedback has played a significant role in increasing traffic and boosting sales.

The brand currently maintains a customer review rating exceeding 99 per cent on the platform.

Advertisement

Future Plans

Looking ahead, Malagasy Vanilla plans to expand its European footprint further by establishing a warehouse in France and increasing sales across the continent.

The company is also developing new products, including vanilla extract and vanilla sugar, while planning to open a physical retail and production facility in Belgium later this year.

In addition, it intends to launch a social-impact initiative aimed at supporting vanilla-growing communities in Madagascar.

Reflecting on the company’s evolution, Rabenandrasana said the business continues to build on her family’s legacy.

“My grandfather worked locally, my father expanded nationally, and now we are building internationally,” she said.

Advertisement

Kindly share this post
Continue Reading

E-Business

FG Must Consider Data Security, Sovereignty in 3MTT Initiative – Stakeholders

Published

on

Kindly share this post

Stakeholders in Nigeria’s digital economy have urged the Federal Government to review its partnership with global recruitment platform Hello.cv under the 3 Million Technical Talent (3MTT) programme, citing concerns over data security, digital sovereignty and the country’s “Nigeria First” policy.

FG Must Consider Data Security, Sovereignty in 3MTT Initiative – Stakeholders

3MTT

The concerns follow the Federal Ministry of Communications, Innovation and Digital Economy’s announcement on May 6 of a 10 million-dollar partnership with Hello.cv aimed at increasing the global visibility of Nigerian technology professionals.

Under the initiative, 20,000 selected 3MTT fellows will receive a global professional profile package, including an Artificial Intelligence (AI)-powered job search agent, a professional curriculum vitae (CV) writer and a personal .cv domain, valued at 500 dollars per participant.

While stakeholders acknowledged the programme’s potential to improve global employment opportunities for Nigerian tech talent, they expressed concerns about the implications of hosting participants’ digital identities and data on a foreign domain.

Chief Executive Officer of Cyberchain and Global Digital Economy Strategist, Engr. Jude Ozinegbe, said the arrangement raised important questions about data ownership and jurisdiction.

According to him, registering domains under an entity outside Nigeria gives that entity a degree of control over activities associated with the domain.

Advertisement

“When you register your domain under a different entity outside your jurisdiction, that entity will have access to whatever is happening within that domain.

“In the long run, the Nigeria Data Protection Commission (NDPC) may have to examine the agreement and assess the security implications of such domain ownership,” he said.

Ozinegbe urged the NDPC to review the security protocols employed by Hello.cv to ensure compliance with Nigeria’s data protection regulations.

Also speaking, Ugonma Egwuatu of ECAM Global Services, an information and communications technology and data protection firm, said the security of data belonging to 20,000 fellows should be of significant interest to regulators.

She noted that while the ministry had the authority to determine how the programme was implemented, there was a need for greater transparency regarding the handling of participants’ personal information.

Advertisement

“The NDPC requires its registered Data Protection Compliance Organisations (DPCOs) to subscribe to the .ng domain.

“If a government ministry permits trainees to operate on a foreign domain, then the commission should examine the arrangement because we are dealing with the data of 20,000 Nigerians,” she said.

Egwuatu also called for clarity on how data generated through the platform would be processed, stored and protected.

“There should be explanations regarding the backend. What are they doing with the data of people who visit these sites? Why use a foreign domain instead of the .ng domain? These are legitimate questions that deserve answers,” she said.

She added that government should ensure appropriate third-party agreements and safeguards were in place before implementing such initiatives.

Advertisement

On his part, Chief Executive Officer of DNS Africa, Dr. Adebunmi Adeola Akinbo, said the objectives of the programme could still have been achieved while leveraging Nigeria’s country code top-level domain.

According to him, Hello.cv could have registered a hello.cv.ng or hellocv.ng domain in collaboration with the Nigeria Internet Registration Association (NiRA).

“The .ng domain can conveniently accommodate such a platform. If Hello.cv intends to onboard millions of Nigerians, it can work with NiRA to create a local domain structure.

“That way, the investment remains within Nigeria, strengthens the digital economy and supports local internet infrastructure,” he said.

Akinbo argued that excluding the .ng domain from the initiative undermined Nigeria’s digital identity and sovereignty.

Advertisement

“As good as the programme may sound, leaving the .ng domain outside this engagement and taking Nigerian data outside the country’s digital jurisdiction is not the best approach,” he said.

Also commenting, Founder and Chief Executive Officer of Precise Financial Systems Ltd., Yele Okeremi, stressed the importance of ensuring that investments in Nigeria’s digital economy create long-term domestic value.

According to him, building a sustainable technology ecosystem requires more than developing skilled professionals.

“Investment, particularly in technology and the knowledge economy, is not just about having smart people.

“It is also about who owns the infrastructure and who ultimately benefits from the value created. Nigeria must ensure it retains as much of that value as possible,” he said.

Advertisement

Similarly, Chief Executive Officer of the Internet Exchange Point of Nigeria (IXPN), Muhammed Rudman, described the use of foreign domains for a government-sponsored initiative as inconsistent with efforts to promote Nigeria’s digital economy.

“I don’t know where this idea came from, but it is unpatriotic for Nigerian companies funded by Nigerian resources to adopt .cv domains instead of .ng.

“Global companies such as Google register country-specific domains like google.ng when operating locally. Registering 20,000 additional .ng domains would improve Nigeria’s online visibility and strengthen the local internet ecosystem,” he said.

Rudman urged the Federal Government to support indigenous digital infrastructure by encouraging the use of the .ng domain.

The 3 Million Technical Talent (3MTT) programme is a flagship initiative of the Federal Ministry of Communications, Innovation and Digital Economy aimed at equipping Nigerians with globally relevant digital skills.

Advertisement

The programme provides free training in areas including software development, artificial intelligence, cloud computing, cybersecurity, data analytics, machine learning, animation, DevOps and user interface/user experience design through a hybrid learning model.

Stakeholders maintained that while the partnership with Hello.cv could expand international employment opportunities for Nigerian technology professionals, greater attention should be paid to safeguarding the country’s digital assets, promoting local internet infrastructure and ensuring compliance with Nigeria’s data protection framework.

Kindly share this post
Continue Reading

Trending